I have two DNS servers on my network where i work. I am also running a win2k AD. My main DC/DNS server is sending out alot of strange DNS requests to my ISP's DNS servers. So many that it is slowing the internet access for my users. I have a Firebox 700 controlling access to my network. When i stop the DNS server service on my main DNS server, the DNS traffic returns to normal.
I scanned the server for spyware and trojans. Did not find any trojans and found a few spyware. After clearing the spyware, the problem did not stop. I have been doing Ethereal Captures and found the the website requests are random and some websites aren't real or cant be reached.
Any suggestions as to what too look for? How can i trouble shoot further this problem? I currently have the service running but blocked outgoing DNS requests from the problem server.
I scanned the server for spyware and trojans. Did not find any trojans and found a few spyware. After clearing the spyware, the problem did not stop. I have been doing Ethereal Captures and found the the website requests are random and some websites aren't real or cant be reached.
Any suggestions as to what too look for? How can i trouble shoot further this problem? I currently have the service running but blocked outgoing DNS requests from the problem server.